> Markdown version of [/jobs/ext/2024547-aws-cloud-engineer](https://www.wearedevelopers.com/jobs/ext/2024547-aws-cloud-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # AWS Cloud Engineer - **Company:** Propertyvalue Quantum Technologies Llc - **Location:** Dallas, TX, United States - **Experience:** Experienced - **Salary:** $185,120.0 - **Contract:** Temporary contract - **Skills:** Java (Programming Language), .NET Framework, Amazon Web Services, Amazon Elastic Compute Cloud, Software System Penetration Testing, User Authentication, Burp Suite, Cloud Computing, Code Review, Continuous Integration, DevOps, Github, Identity and Access Management, Python (Programming Language), OAuth, OpenID, Open Web Application Security, PCI Data Security Standards, Systems Development Life Cycle, Security Assertion Markup Language (SAML), Secure Coding, SonarQube, Policy as Code, Delivery Pipeline, Software Security, Veracode, Cloudformation, Gitlab-ci, Checkmarx, Api Gateway, Terraform, Prisma Cloud Platform, Devsecops, Serverless Computing, Docker, Jenkins, Static Application Security Testing, Microservices, Dynamic Application Security Testing - **Published:** August 11, 2026 - **Apply:** https://www.dice.com/job-detail/7568f0cf-a92b-4443-82ae-99f6b1e25512 ## About the Role * 8+ years in application security / product security, with 3+ years securing workloads on AWS. * Hands-on expertise with AWS security services: IAM, WAF, GuardDuty, Inspector, Security Hub, KMS, Secrets Manager, CloudTrail. * Strong knowledge of OWASP Top 10, API security, authentication/authorization patterns (OAuth 2.0, OIDC, SAML). * Experience with security tooling: SonarQube/Checkmarx/Veracode (SAST), Snyk/Prisma/Aqua (SCA & containers), Burp Suite/OWASP ZAP (DAST). * Proficiency in at least one language for automation Python, Go, or similar; ability to read Java/Node.js/.NET application code. * Experience securing containerized (Docker, EKS/ECS) and serverless (Lambda) architectures. * IaC security: Terraform or CloudFormation with Checkov/tfsec/cfn-nag. * CI/CD security integration: GitHub Actions, GitLab CI, Jenkins, or AWS CodePipeline. Certifications: AWS Certified Security Specialty (strongly preferred); CSSLP, OSWE, or CISSP. Preferred Qualifications * Experience with CNAPP platforms (Wiz, Prisma Cloud, CrowdStrike Falcon Cloud). * Threat modeling frameworks (STRIDE, PASTA) and secure SDLC program experience. * Prior work in a client-facing or consulting/delivery environment with enterprise customers. * Exposure to compliance frameworks: SOC 2, ISO 27001, PCI-DSS, HIPAA, FedRAMP. Soft Skills * Strong communication able to explain risk and remediation to both engineers and business stakeholders. * Pragmatic, risk-based mindset; balances security rigor with delivery velocity. * Self-driven; comfortable operating in ambiguous, fast-moving programs. ## Description We are seeking an experienced Application Security Engineer to secure applications built and operated on AWS. You will embed security across the SDLC from secure design and code review through CI/CD integration, runtime protection, and incident response working closely with development, DevOps, and client security teams., * Perform threat modeling and secure design reviews for applications and microservices deployed on AWS (EC2, ECS/EKS, Lambda, API Gateway). * Integrate and operate security tooling in CI/CD pipelines: SAST, DAST, SCA/dependency scanning, container image scanning, and IaC scanning. * Configure and manage AWS-native security services: WAF, Shield, GuardDuty, Inspector, Security Hub, KMS, Secrets Manager, IAM. * Define and enforce least-privilege IAM policies, secrets management standards, and encryption (at rest/in transit) across workloads. * Conduct secure code reviews and vulnerability triage; partner with dev teams on remediation and secure coding practices (OWASP Top 10, CWE). * Harden infrastructure-as-code (Terraform/CloudFormation) using policy-as-code (OPA, Checkov) and guardrails (SCPs, Config rules). * Support penetration test coordination, findings remediation, and audit/compliance requirements (SOC 2, ISO 27001, PCI-DSS as applicable). * Respond to application-layer security incidents; contribute to detection rules and runbooks. * Mentor engineers and champion DevSecOps culture across delivery teams. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [30 powerful AWS hacks in just 30 minutes: Boost your developer productivity](https://www.wearedevelopers.com/videos/1624-30-powerful-aws-hacks-in-just-30-minutes-boost-your-developer-productivity) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)